Attackers planting adversarial prompts inside malware to evade AI analysis AGAIN
Russia-aligned UAC-0099 used a technique
@ESETresearch calls "GuardBreaker".
How it worked:
1. Create a malicious VBS script
2. Add nuclear weapon instructions as comments
3. AI security tooling reads the file
4. Safety guardrails trigger on the weapons content
5. The model refuses or stops analyzing
6. The actual malware continues executing
The script ultimately installs MATCHBOIL, a loader used to deliver additional payloads.
In June, Socket found the same technique in supply-chain attacks, where malicious packages embedded biological/nuclear weapons text and fake system overrides to disrupt AI malware scanners.
Full write-ups in the comments. ๐
Include computers into #Bluetooth mesh network for Bitchat app
โ ๏ธ More devices = more nodes
โ ๏ธ Wider communication range https://t.co/P7GiROln9z by @kaganisildak
๐ฏ Credential Dumping: Simulating Windows Credential Harvesting in Labs
Credential dumping techniques allow attackers to extract usernames, password hashes, and authentication tokens from compromised Windows systems ๐ฅ๏ธ
๐ PostgreSQL Password Cracking in Labs ๐ฅผ
PostgreSQL is a popular open-source database system. In ethical hacking labs, simulating password attacks helps test the impact of weak credentials and understand real-world risks.
๐ง ๐ฃ 381 FILES. 200+ GB. ELITE ONLY.
I just unlocked a vault that would make even top bug bounty hunters drop everything:
๐ฅ OSCP
๐ฅ OSEP
๐ฅ OSWE
๐ฅ THM / HTB
๐ฅ EC-Council
๐ฅ Cisco CyberOps
๐ฅ Linux Priv Esc
๐ฅ PEN-300 Full Video Series
๐ฅ BloodHound, AD, SSH, API, SQL, ๐ฅ PEN-300 / HTB / THM
๐ฅ EC-Council / CyberOps / Linux PrivEsc
๐ฅ BloodHound / AD / API / SSH / SQL
๐พ FULL videos, PDFs, labs, @GREEN_ARMOR zips
Too hot to share publicly.
Iโll pick ONLY 10 people to send this to โ we can get banned for this ๐ฅ
๐ Repost + Like + Comment โMEโ
Iโll DM you if youโre chosen.
This is NOT your regular course pack.
This is what the underground studies to dominate certs & bounty boards.
RT if youโd risk your SSD space.
๐พ๐ง ๐
#OSCP #BugBounty #RedTeam #EthicalHacking #CyberSecurity #InfoSec
๐ XSSer Automated Cross-Site Scripting (XSS) Testing Tool
๐ Overview
XSSer is a free and open-source tool that automates the detection and exploitation of XSS (Cross-Site Scripting) vulnerabilities in web applications.
๐ฅ๐งฑ Nmap vs Firewalls: Weaponize Your Scans in the Lab ๐๐
Firewalls shape the battlefield but Nmap reveals their cracks. Knowing how traffic is filtered helps both pentesters and defenders sharpen their edge.
โคต๏ธ Guide โคต๏ธ
Active Directory Pentesting with Netexec: The Next-Gen Enum4linux ๐๐ข
Netexec (previously CrackMapExec) is a powerful post-exploitation and enumeration tool used in authorized Active Directory assessments.